Prompt

How do I ensure my passive candidate sourcing workflow with a resume database is compliant with privacy and consent rules?

Latest observation

Jul 26, 2026 · OpenAI APIWeb search: off

To keep a passive-candidate sourcing workflow compliant, treat resume data as personal data and make sure every step has a lawful basis, clear notice, and appropriate retention/usage controls. Exact rules vary by country/state, but this is the practical checklist that covers most privacy laws and hiring regulations.

1) Map what data you collect and why

Document:

  • What fields you use from the resume database
  • Where the data came from
  • Why you need each field
  • Who can access it
  • How long you keep it

Best practice: only collect and use data that is relevant to recruiting.

2) Verify the source of the resume database

Make sure the database provider:

  • Collected resumes lawfully
  • Gave candidates proper notice
  • Has the right to share the data with employers/recruiters
  • Can support deletion/opt-out requests
  • Has a valid data-processing agreement with you if they act as a processor

If the database is scraped, aggregated without notice, or unclear on consent, risk is higher.

3) Identify the lawful basis for outreach

Depending on jurisdiction, you may rely on:

  • Consent: candidate explicitly agreed to be contacted
  • Legitimate interests: you can justify contact for recruiting, but must balance against candidate privacy rights
  • Contract / pre-contract steps: usually less common for passive sourcing
  • Other local legal bases under employment/privacy law

Important:

  • Even where legitimate interests is allowed, you usually still need notice and an easy opt-out.
  • For some communications, especially marketing-like outreach, consent may be required.

4) Give a privacy notice at the right time

Candidates should know:

  • Who you are
  • What data you use
  • Where you got it
  • Why you’re contacting them
  • Whether profiling or automated screening is used
  • Who you may share it with
  • How long you keep it
  • Their rights: access, deletion, correction, objection, restriction
  • How to opt out of future contact

If the candidate didn’t provide the data directly, you may need to provide notice soon after first contact or at collection, depending on local law.

5) Respect consent and opt-out signals

If you use consent:

  • Store the consent record
  • Record what they consented to, when, and how
  • Make withdrawal easy
  • Stop outreach immediately if they opt out

If you use legitimate interests:

  • Still provide a simple do not contact option
  • Honor suppression lists across systems

6) Limit use to recruiting purposes

Don’t:

  • Use resume data for unrelated marketing
  • Share it broadly internally
  • Feed it into tools without a legal review
  • Reuse old candidate data for new roles without checking whether that’s permitted

If you want to contact candidates for different roles, make sure your notice and legal basis cover that use.

7) Be careful with sensitive data

Resumes may include or imply:

  • Age
  • Race/ethnicity
  • Religion
  • Health/disability
  • Family status
  • Immigration status
  • Salary history
  • Photos or other protected characteristics

Avoid:

  • Collecting unnecessary sensitive data
  • Using sensitive data in search, ranking, or filtering unless legally permitted
  • Making decisions based on protected characteristics

If your workflow uses AI or automated ranking, review for bias and legal constraints.

8) Set retention and deletion rules

Define retention periods for:

  • Active candidates
  • Rejected candidates
  • Unresponsive prospects
  • Opt-outs/suppression records

General principle:

  • Keep data only as long as needed for the hiring purpose
  • Delete or anonymize when no longer needed
  • Keep minimal suppression data longer if needed to honor “do not contact”

9) Put vendor and access controls in place

Use:

  • Role-based access
  • Logging and audit trails
  • Encryption in transit and at rest
  • Processor/vendor agreements
  • Cross-border transfer safeguards if data moves between countries

Limit access to recruiters and hiring staff who actually need it.

10) Keep records of compliance

Maintain:

  • Source documentation
  • Notices provided
  • Consent logs or legitimate-interest assessments
  • Opt-out/suppression records
  • Data processing agreements
  • Retention/deletion procedures
  • Security incident response plan

11) Review local laws before outreach

Relevant laws may include:

  • GDPR / UK GDPR
  • EU ePrivacy rules
  • CCPA/CPRA
  • State privacy laws
  • Employment and anti-discrimination laws
  • Canada, Australia, Singapore, Brazil, and other local privacy regimes

Some countries require specific employee/candidate notices or restrictions on cross-border transfers and automated decision-making.

12) A practical compliant workflow

A safer sourcing flow looks like this:

  1. Verify database provider’s legal basis and notices
  2. Limit searches to job-relevant criteria
  3. Send a first message that includes identity, source, purpose, and privacy notice
  4. Offer opt-out / unsubscribe
  5. Record the contact and any consent/objection
  6. Suppress opted-out candidates from future outreach
  7. Delete or archive data according to retention rules
  8. Review vendor, AI, and bias risks regularly

Simple rule of thumb

If you can’t answer these clearly, pause and review:

  • Why do we have this candidate’s data?
  • What told them we would use it this way?
  • What legal basis allows us to contact them?
  • How do they say no?
  • When do we delete it?

If you want, I can also give you:

  1. a compliance checklist,
  2. a candidate outreach privacy notice template, or
  3. a workflow diagram for passive sourcing.

Observation history

See 1 earlier observation

Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (2 observations for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.